QR 코드를 스캔하여 다운로드하세요.
BTC $70,228.92 -0.34%
ETH $2,105.48 +0.63%
BNB $637.49 -0.35%
XRP $1.44 +0.68%
SOL $86.94 +0.15%
TRX $0.2786 +0.29%
DOGE $0.0963 -0.28%
ADA $0.2702 +0.15%
BCH $533.83 +1.25%
LINK $8.85 +0.34%
HYPE $31.38 -2.97%
AAVE $112.98 +0.71%
SUI $0.9654 -1.02%
XLM $0.1598 -0.75%
ZEC $241.50 +1.88%
BTC $70,228.92 -0.34%
ETH $2,105.48 +0.63%
BNB $637.49 -0.35%
XRP $1.44 +0.68%
SOL $86.94 +0.15%
TRX $0.2786 +0.29%
DOGE $0.0963 -0.28%
ADA $0.2702 +0.15%
BCH $533.83 +1.25%
LINK $8.85 +0.34%
HYPE $31.38 -2.97%
AAVE $112.98 +0.71%
SUI $0.9654 -1.02%
XLM $0.1598 -0.75%
ZEC $241.50 +1.88%

느린 안개: ClawHub는 점차 공격자가 공급망 독을 실행하는 새로운 목표가 되고 있습니다

2026-02-09 10:53:52
수집

据慢雾监测,开源 AI Agent 项目 OpenClaw 的官方插件中心 ClawHub 正逐渐成为攻击者实施供应链投毒的新目标。

由于平台缺乏完善、严格的审核机制,已有大量恶意 skill 混入其中,并被用于传播恶意代码或投放有害内容,给开发者和用户带来潜在安全风险。根据 Koi Security 的报告,在对 2,857 个 skills 的扫描中识别出 341 个恶意 skills,反映出典型的"插件/扩展市场供应链投毒"形态。

慢雾建议,不要把 SKILL.md 的"安装步骤"当成可信来源,任何要求复制粘贴执行的命令都应先审计;警惕"需要输入系统密码/授予辅助功能/系统设置"的提示,这往往是风险升级点;优先从官方渠道获取依赖与工具,避免执行来源不明的安装脚本。

app_icon
ChainCatcher Building the Web3 world with innovations.